Create OIDC Client
POST/v3/config/extension/oidc/client
Creates an OpenID Connect client. The client enables passwordless login with EUDI Wallet by requesting verifications from individuals. During client creation, a presentation definition specifies which credentials to request - appearing as a QR code or deep link on the authentication page. A presentation definition belongs to at most one client. Give exactly one of identityMatchingAttributes or callbackURI with callbackSecret. The answer holds the generated clientId and clientSecret.
Request
- application/json
Body
The ID of the presentation definition to use for this client. A presentation definition belongs to at most one client. If the presentation definition has a transaction data template, the template must be login_risk_transaction_non_ts12 or login_risk_transaction. No credential may come with its own transaction data (TS12: payment wallet attestation, software statement, QESAC, SCA credential types): such a definition has another purpose than login.
The name of the client
The redirect URIs for the client. The redirect_uri of an authorisation request must match one of them exactly.
The web origins of your application.
identityMatchingAttributes object
A map of credential identifiers to claim paths used as linking values for identity matching. Each key identifies a credential: the vct of an SD-JWT credential, the doctype of an mdoc credential, or a type value of a W3C credential. The value is the dot-separated path to the claim within that credential. The value of that claim becomes the sub. Give one entry for each credential in the DCQL query of the presentation definition. The key and the path must exist in that DCQL query. Example: {"urn:eudi:pid:1": "email"} uses the email claim of the PID credential for identity matching. Do not send it together with callbackURI.
The URI at which a sub value will be calculated and returned according to the sent presentation. Use an HTTPS endpoint. The endpoint receives the presentations in a POST request and must answer with status 200 and a JSON object that holds sub. Do not send it together with identityMatchingAttributes.
The secret used to access the callbackURI. Required when callbackURI is set.
Possible values: <= 140 characters
The text that describes the login to the user in the EUDI Wallet, for example Log in to your online bank account. Required when the presentation definition has a transaction data template. Not allowed when the presentation definition has no transaction data. The EUDI Wallet accepts at most 140 characters.
Responses
- 201
- 400
- 401
- 500
Client created
Response Headers
Cache-Control string
Indicates that the response should not be cached.
- application/json
- Schema
- Example (from schema)
Schema
The ID of the created client
The secret of the created client
{
"clientId": "string",
"clientSecret": "string"
}
Bad request. The provider answers with error and error_description when the body is not valid JSON, when presentationDefinitionId, name or callbackSecret is missing, when both or none of identityMatchingAttributes and callbackURI are given, or when the presentation definition already belongs to a client. The answer has errorCode and errorDescription when the Passwordless Login extension is not enabled.
Response Headers
- application/json
- Schema
- Example (from schema)
Schema
- Provider error
- API error
The error code, for example invalid_request, not_found or server_error
The reason for the error
{
"error": "invalid_request",
"error_description": "A client has already been created for the provided Presentation Definition"
}
Unauthorized
Response Headers
- application/json
- Schema
- Example (from schema)
Schema
{
"errorCode": 400,
"errorDescription": "Bad input parameter"
}
The validation of the presentation definition, of identityMatchingAttributes or of transactionDataAction refused the request, or an internal error occurred. A refusal holds the reason in error_description. The API answers with errorCode and errorDescription when it cannot reach the provider.
Response Headers
- application/json
- Schema
- Example (from schema)
Schema
- Provider error
- API error
The error code, for example invalid_request, not_found or server_error
The reason for the error
{
"error": "invalid_request",
"error_description": "Transaction data action is required when presentation definition has transaction data"
}